GEN005511 - The SSH client must be configured to not use Cipher-Block Chaining (CBC) based ciphers

Information

The CBC mode of encryption as implemented in the SSHv2 protocol is vulnerable to chosen plaintext attacks and must not be used.

Solution

Edit the configuration file and remove any ciphers other than those with the 'aes' prefix and the '-ctr' suffix.

See Also

https://iasecontent.disa.mil/stigs/zip/U_HPUX_11-31_V1R19_STIG.zip

Item Details

Category: SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|SC-13, CAT|II, CCI|CCI-000366, Rule-ID|SV-35193r1_rule, STIG-ID|GEN005511, Vuln-ID|V-22462

Plugin: Unix

Control ID: 6342d7c0b6d35b2465328087163d1071e74b078eebb2ce36b6f5c9a6bc789bd1